SPEAK-O / PRIVACY

Privacy, without
the small-print fog.

Effective 2 September 2026 · Publisher and data controller: Rekh · Contact: hello@rekh.dev

1. Scope

This policy applies to Rekh's Speak-O Chrome extension and these Speak-O product pages. Speak-O is an open-source, accountless Article Reader for Chrome. Rekh does not operate a Speak-O speech backend, account service, analytics service, telemetry pipeline, crash reporter, or remote diagnostics service.

Chrome Web Store Limited Use

Speak-O's handling of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

2. Data we handle

Article and Selection text

When you explicitly start a Reading Session, Speak-O reads the Article or Selection needed for that session. It creates a fixed Article Snapshot locally so the current source mapping remains stable. Speak-O does not send Article text to Rekh, persist it as reading history, or upload it for analytics.

Provider Credentials

If you choose ElevenLabs or Speechify, you enter your own Provider Credential into the extension. The credential is kept in Chrome storage and is sent only to the selected Provider's API for the direct Provider Connection. Rekh never receives the credential. Session-only storage is the default; choosing Remember on this device uses local Chrome profile storage without additional application-level encryption.

Generated audio and Speech Alignment

Cloud Voice audio and Speech Alignment may be retained in a bounded, session-only Session Buffer so playback and a recent Previous action can continue without unnecessary regeneration. They are cleared when the Reading Session or extension session ends. Speak-O does not keep completed audio downloads.

Preferences and technical state

Speak-O stores local preferences such as theme, dock, Playback Speed, Narration Language, Voice choices, and highlighting behavior. A minimal active-session descriptor stores identifiers, Provider, mode, cursor, and status; it excludes Article text and Source Page URL. The extension does not use Chrome Sync, behavioral tracking, or a Rekh user identifier.

3. How data is used

  • Extract and speak the Article or Selection that you explicitly request.
  • Map the active Reading Position back to the original Source Page.
  • Send bounded Cloud Voice source text directly to the Provider you select.
  • Keep local preferences, Provider Connection state, playback recovery, and Speech Alignment available for the active session.
  • Produce redacted diagnostics locally only when you choose Copy redacted diagnostics.

Rekh does not sell this data, use it for advertising or profiling, transfer it for unrelated purposes, or use it to train machine-learning models.

4. Direct Provider connections

Chrome or the operating system may process text spoken through the Browser Voice Mode exposed by Chrome's tts API. Speak-O does not claim that Browser Voice Mode is offline.

ElevenLabs receives only the bounded source text needed by its Generation Window, sent directly from the extension to the API Region you select with your Provider Credential. ElevenLabs controls its own processing, retention, billing, and policy. See its privacy material.

Speechify receives only the bounded source text needed by the active Generation Window, sent directly from the extension using your Provider Credential. Speechify controls its own processing, retention, billing, and policy. See its privacy material.

Rekh is not an intermediary for either Cloud Voice Provider. Each Provider Connection is independent, and disconnecting one removes only its local credential, cached metadata, Provider work, and optional host permission.

5. Storage and security

Speak-O uses Chrome extension storage on your device. Provider Credentials default to chrome.storage.session; remembered credentials use chrome.storage.local. Speak-O does not add application-level encryption. Protect your Chrome profile and rotate a Provider Credential if you suspect exposure.

When a Provider Connection is active, traffic to ElevenLabs or Speechify uses the HTTPS endpoint selected by the Provider. Rekh has no server-side copy of the Article text, Provider Credential, generated audio, Reading Position, or diagnostics.

6. Permissions

  • activeTab and scripting permit temporary, explicit Source Page access after a toolbar, command, or Selection action.
  • contextMenus provides the explicit Read Selection action.
  • tts speaks through a Browser Voice.
  • storage retains preferences and the active session state.
  • offscreen supplies the audio-only document needed for Cloud Voice playback.
  • ElevenLabs and Speechify origins are optional and requested only for the Provider Connection you choose.

7. Diagnostics

Diagnostics are generated locally only when you choose to copy them. They contain structural metadata such as Provider, mode, status, error code, and duration. They exclude Article prose, Provider Credentials, audio, and full URLs by default. You decide whether and where to share the copied text.

8. Your choices

  • Use Chrome Voice and do not create a Cloud Voice Provider Connection.
  • Leave Remember on this device off for session-only Provider Credential storage.
  • Disconnect ElevenLabs or Speechify independently from Speak-O settings.
  • Clear extension storage or uninstall Speak-O to remove local preferences, remembered credentials, and session state from that Chrome profile.
  • Use Selection reading when automatic Article extraction is unsuitable.

9. Changes and contact

Material changes are recorded in the public repository and reflected on this page. Email privacy or security concerns to hello@rekh.dev. Do not include a Provider Credential, Article prose, generated audio, or an unredacted URL.